AZL-105051

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105051.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105051
Upstream
  • CVE-2026-102253
Published
2026-09-29T21:17:13Z
Modified
2026-09-30T14:18:01Z
Summary
CVE-2026-102253 affecting package iperf3 3.17.1-6
Details

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.

References

Affected packages

Azure Linux:3 / iperf3

Package

Name
iperf3
Purl
pkg:rpm/azure-linux/iperf3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.17.1-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105051.json"